Most teams that use AI have a policy. Far fewer can show it runs. That gap - between the document that exists and the practice an outsider could verify - is where almost every AI-governance problem actually lives. It is also where a board question, an auditor, a customer’s security review, or a regulator’s first email tends to land.
This is not a test you pass or fail. It is a map, and wherever you stand on it is a fine place to be standing. Even if you have nothing written down yet, you are not behind - you are at the beginning, which is a real place to start. Answer four questions honestly and you will know exactly where you stand and what the single next piece of work is. Most teams find they are further along than they feared on the first rung, and further back than they assumed on the third. Both are useful to know.
The four rungs
Rung 1 - Do you have a written AI-use policy?
What this is: a document that says how your organization uses AI - which tools, for what, with what limits.
Where most teams are: further along than they think. If anything is written down, even a single page, you clear this rung.
What good looks like: one policy your people could actually find and read, not a clause buried in a handbook no one opens.
If you stopped here, your next step: write one page. Not a legal document. What you use, what you do not allow, who to ask.
Rung 2 - Can you name who it applies to?
What this is: knowing which people and roles the policy actually governs - including the people who act on AI output, not only those who operate the tool.
Where most teams are: they have the policy but have never mapped it to actual humans.
What good looks like: a short list of the roles that touch AI, with the higher-stakes ones (whose AI use affects customers, patients, money, or decisions) marked as needing more.
If you stopped here, your next step: list the roles. Mark the high-stakes ones. That is the whole rung.
Rung 3 - Can you show, today, that it was followed?
What this is: evidence. Not “we told everyone.” A record that the policy was applied - who was trained, on what, when - and, for any AI that acts on its own, proof of what it was allowed and not allowed to do.
Where most teams are: this is the rung where the climb gets real. Most have the policy and even the scope, and stop here. Having a rule and showing the rule was followed are two different things.
What good looks like: a folder, not a story. If someone asked “show me,” you could hand them something.
If you stopped here, your next step: pick one AI use that matters and start keeping the record for it. One is enough to begin.
Rung 4 - Could you show someone outside?
What this is: the same evidence, but checkable by a person who does not work for you and does not take your word - a board member, an auditor, a customer’s security team, a regulator.
Where most teams are: almost no one is here yet, especially for AI agents that act on their own. This is the frontier, not the baseline. Being below it is normal.
What good looks like: an outsider can verify what your AI was constrained to do, including what it refuses to do, rather than trust that it behaved.
If you stopped here, your next step: this is the work I do, and the honest place where a conversation helps most. More below.
Where you land
- Rungs 1 to 2 only: you have the document, not yet the practice. Common, and fixable in weeks.
- Through rung 3: you can show it runs, internally. You are ahead of most.
- Rung 4: you can prove it to an outsider. Rare. If you run AI agents, rarer still.
If you got to rung three and stopped, you are in good company. Most teams have never been asked to show their policy runs, only to have one. That is not a mark against you. It is simply the next piece of work, and it is reachable.
Two ways forward, and the free one is real
Walk it yourself. Everything here is yours to use, and each rung above names its own next step. For the fuller walk against the EU AI Act’s literacy duty, read The August 2 Deadline Moved. The Architecture Question Did Not. - no signup, no catch. Most teams can close the first three rungs on their own.
Or bring me in. If you want a hand - a working session for your team against this diagnostic, or a straight answer on whether your AI-agent governance would survive an outsider’s first question - that is a short call. One conversation, and you leave knowing your next three moves. Book a call or email erin@evoked.dev.
You do not need me to climb the first three rungs. You might want me for the fourth. Either way, you finish knowing where you stand, which is the whole point of a map.
For context, not alarm: the EU AI Act’s AI-literacy duty (Article 4) has been in force since 2 February 2025, and national authorities begin supervising and enforcing it from 2 August 2026. The Digital Omnibus - endorsed by the European Parliament on 16 June 2026 and given final approval by the Council on 29 June 2026 - softened the standard: providers and deployers must support the development of their staff’s AI literacy rather than guarantee a specific level. It did not defer Article 4. It deferred the heavier high-risk obligations, to 2 December 2027 for use-based high-risk systems and 2 August 2028 for AI embedded in regulated products. The literacy duty is current, the standard is proportionate, and the bar is lower than the fear. This is practical guidance, not legal advice.
The document is not the practice. The map is not the climb. But you cannot start the climb until you know which rung you are on.
Sources: European Commission, “AI Literacy - Questions and Answers,” digital-strategy.ec.europa.eu; “Article 4: AI literacy,” artificialintelligenceact.eu; Morrison Foerster, “EU Digital Omnibus on AI: What Is in It and What Is Not?”; Sidley, “EU Lawmakers Reach Provisional Agreement to Delay Key EU AI Act Obligations.” Verified July 2026.
Licensed under Creative Commons Attribution 4.0 (CC BY 4.0). Free to use, share, and adapt - including the four-rung diagnostic - with attribution to Erin Stanley, Evoked.